Win 7 Home Antivirus Gone?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Gelaton, Dec 20, 2011.

  1. Gelaton

    Gelaton Private E-2

    Okay, today while I was out driving around I got hit with Windows 7 Home Protection 2012 (Between Noon and 4). I had some Firefox tabs open, iTunes, ect. Then when I saw that I had it, I closed the program (I looked for anything suspicious in my task manager but I didn't see anything suspicious). I booted up Vipre and it found FakeAlert.Trojan, but when I tried to clean the file there was an error and I was unable to delete/quarantine it. So I attempted a system restore, only to find that I couldn't run anything. I would get a popup (from Win7 Antivirus) saying that any .exe I tried to open was infected, and upon clicking the "Continue Unprotected" the program wouldn't open. After a few minutes of trying to do a work around (Run as admin, open with, and so on) with different files I forced a power off and booted in safe mode. From safe mode I ran a system restore but it was unfortunately unsuccessful and I was again greeted by Win7 AV 2012. This time however I couldn't open either of my legitimate anti-viruses (I use Vipre and Malwarebytes) so I forced a power off again. When my computer rebooted I quickly opened Malwarebytes and ran a scan. It found two copies of qvy.exe and I hit the clean button. Malwarebytes reported that they had been successfully removed but them my system rebooted without a prompt (About 6). Since that reboot there have been no obvious signs of the virus. I, however, cannot run .exe files without a "Windows does not recognize that file, please select the program to open with" window opening. So I opened my laptop and started scrounging for information. Then I realized both Steam and Vipre were running on my computer. So I right clicked my Vipre icon and clicked "Scan with Vipre" and sure enough Vipre opened. So I did the same with Firefox, when I was prompted to pen it with something I chose firefox and sure enough firefox opened. I then opened iTunes with itself just to see if it worked all around, and it did. So here I am typing this from the infected computer. What the heck is going on? (Also thanks if you read through all of this.)
     
  2. Gelaton

    Gelaton Private E-2

    Update (I hope this doesn't violate the bump policy):
    I tried fixing the registry twice (both times it said I did it right but it didn't fix anything). Then decided to try a system restore (as I said before I can open almost every file with some work around). But as far as I can tell it didn't do anything (still can't "run" .exes files). Still no obvious signs of Win 7 AV.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Download the below file to your Desktop. Once saved on your Desktop, Right click on it and select Install

    EXEfix

    Then see if you can run EXE files.
     
  4. Gelaton

    Gelaton Private E-2

    I downloaded and installed but I still can't run .exe files without going through my work around. Also ran Vipre and Malwarebytes over night, but they turned up nothing. And thanks for the warm welcome :wave .
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay since you are having problems running programs, we will skip some of our normal prelimary steps and jump right to the cleaning phase for malware. Please run as much of the below as you can and attach the logs.

    Vista & Windows 7 Malware Removal/Cleaning Procedure
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds